CVE-2009-4840
Roxio CinePlayer 3.2 - Remote Code Execution via IAManager ActiveX SetIAPlayerName Method
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2009-4840. PoCs published by His0k4.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in Roxio CinePlayer 3.2 via the IAManager.dll component. It uses heap spraying to achieve remote code execution by overflowing the SetIAPlayerName method with a crafted buffer containing shellcode.
Description
Heap-based buffer overflow in the IAManager ActiveX control in IAManager.dll in Roxio CinePlayer 3.2 allows remote attackers to execute arbitrary code via a long argument to the SetIAPlayerName method.
Exploits (1)
This exploit targets a buffer overflow vulnerability in Roxio CinePlayer 3.2 via the IAManager.dll component. It uses heap spraying to achieve remote code execution by overflowing the SetIAPlayerName method with a crafted buffer containing shellcode.